nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-47464 CVE-2024-47464
MEDIUM
Authenticated Path Traversal Vulnerability Leads to a Remote Unauthorized Access to Files
Record summary
CVE-2024-47464 has a selected CVSS score of 6.8 (medium).
Description
An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to a remote unauthorized access to files.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 6, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
HPE Aruba Networking Access Points, Instant AOS-8, and AOS-10Browse Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Access Points, Instant AOS-8, and AOS-10Default status: affected | CVE List | AOS-10.4.x.x: 10.4.1.4 and below to ≤ <=10.4.1.4 | affected |
| Instant AOS-8.12.x.x: 8.12.0.2 and below to ≤ <=8.12.0.2 | affected | ||
| Instant AOS-8.10.x.x: 8.10.0.13 and below to ≤ <=8.10.0.13 | affected |
References
2support.hpe.com
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04722en_us&docLocale=en_US